logo

Bootstrap script exposes PyPI to domain takeover attacks

ID: a59316a0-1f42-546a-ae5a-bec9e9de54a6

STIX ID: report--a59316a0-1f42-546a-ae5a-bec9e9de54a6

Feed Name: ReversingLabs Blog

Threat Score
50/100

Date Published: 2025-11-26

Date Updated: 2026-04-29

Author: Vladimir Pezo

...
...

ReversingLabs discovered that legacy PyPI bootstrap scripts fetch and execute code from the abandoned python-distribute.org domain, creating a domain-takeover supply-chain vulnerability affecting numerous packages; researchers produced a PoC, enumerated affected projects and IoCs, and warned that while no abuse of this domain was observed, comparable incidents (e.g., the npm fsevents compromise) demonstrate the real-world risk of such takeovers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.